30 privacy laws and frameworks, one reference
From GDPR and CCPA/CPRA to LGPD, PIPL, APPI, and ISO 27701 — the global data-protection landscape with jurisdiction, year, and enforcement type.
What is Privacy compliance automation?
Privacy frameworks and laws govern the collection, processing, storage, and transfer of personal data. They establish individual rights, organisational obligations, and enforcement mechanisms. The global landscape has expanded rapidly since 2018: more than 130 countries now have data-protection legislation, and most enterprises must comply with three or more privacy regimes simultaneously. This reference catalogues 30 of the most consequential privacy frameworks worldwide.
The fragmented privacy compliance burden
- GDPR-style laws exist in over 130 countries — each with subtly different definitions of personal data, lawful basis, and transfer rules
- Sector-specific laws (HIPAA, FERPA, GLBA, COPPA) layer additional requirements on top of general privacy regimes
- Cross-border transfers require legal mechanisms (SCCs, BCRs, adequacy decisions) that change as adequacy decisions are challenged
- Subject-rights workflows (access, erasure, portability, opt-out) must be implemented across every data store the organisation operates
A four-step operational model
Map your data flows
Identify every system that processes personal data, the categories collected, the legal basis for processing, and the jurisdictions involved.
Apply the controlling law per data subject
Most laws apply based on the data subject's residency or location at the time of processing, not the company's headquarters.
Implement subject-rights workflows
Standardise access, rectification, erasure, portability, and opt-out workflows so a single request can be honoured across all in-scope systems.
Document and review continuously
DPIAs, ROPAs, and breach notification procedures are continuous obligations — not one-time deliverables.
Complete Privacy Frameworks Reference (30)
Every major privacy law and framework worldwide — full name, jurisdiction, year of effect, and whether the regime is mandatory or voluntary.
| Framework / Law | Full Name | Jurisdiction | Year | Type |
|---|---|---|---|---|
| GDPR | General Data Protection Regulation | EU | 2018 | Mandatory |
| CCPA/CPRA | California Consumer Privacy Act / Rights Act | USA (California) | 2020/2023 | Mandatory |
| HIPAA Privacy Rule | Health Insurance Portability and Accountability Act | USA | 1996 | Mandatory |
| PIPEDA | Personal Information Protection and Electronic Documents Act | Canada | 2000 | Mandatory |
| LGPD | Lei Geral de Proteção de Dados | Brazil | 2020 | Mandatory |
| PDPA | Personal Data Protection Act | Thailand / Singapore | 2022 / 2012 | Mandatory |
| POPIA | Protection of Personal Information Act | South Africa | 2021 | Mandatory |
| APPI | Act on the Protection of Personal Information | Japan | 2005 | Mandatory |
| PIPL | Personal Information Protection Law | China | 2021 | Mandatory |
| PDPB | Personal Data Protection Bill | India | Pending | Proposed |
| Privacy Act | Privacy Act of 1974 / Privacy Act 1988 | USA / Australia | 1974 / 1988 | Mandatory |
| ePrivacy Directive | EU Cookie and Electronic Communications Directive | EU | 2002 | Mandatory |
| NIST Privacy Framework | Privacy Framework v1.0 | USA | 2020 | Voluntary |
| ISO/IEC 29100 | Privacy Framework Standard | International | 2011 | Voluntary |
| ISO/IEC 29101 | Privacy Architecture Framework | International | 2013 | Voluntary |
| ISO/IEC 27701 | Privacy Information Management System | International | 2019 | Voluntary/Certifiable |
| OECD Privacy Guidelines | Guidelines on the Protection of Privacy and Transborder Data Flows | International | 1980 / 2013 | Voluntary |
| APEC Privacy Framework | Asia-Pacific Economic Cooperation Privacy Framework | Asia-Pacific | 2004 / 2015 | Voluntary |
| FTC Act Section 5 | Federal Trade Commission Unfair/Deceptive Practices | USA | 1914 | Mandatory |
| FERPA | Family Educational Rights and Privacy Act | USA | 1974 | Mandatory |
| COPPA | Children's Online Privacy Protection Act | USA | 1998 | Mandatory |
| GLBA | Gramm-Leach-Bliley Act | USA | 1999 | Mandatory |
| SHIELD Act | Stop Hacks and Improve Electronic Data Security Act | USA (NY) | 2020 | Mandatory |
| KVKK | Personal Data Protection Law | Turkey | 2016 | Mandatory |
| PDPL (KSA) | Personal Data Protection Law | Saudi Arabia | 2021 | Mandatory |
| BCR | Binding Corporate Rules (GDPR mechanism) | EU | Ongoing | Voluntary |
| SCCs | Standard Contractual Clauses | EU | 2021 | Voluntary |
| Privacy Shield (defunct) | EU-US Privacy Shield Framework | EU / USA | 2016–2020 | Defunct |
| DIFC DP Law | Dubai International Financial Centre Data Protection Law | UAE | 2020 | Mandatory |
| ADGM DP Regulations | Abu Dhabi Global Market Data Protection Regulations | UAE | 2021 | Mandatory |
Outcomes for security teams
Fines now reach the hundreds of millions
GDPR maximum penalties are €20M or 4% of global turnover. CCPA/CPRA, LGPD, and PIPL all carry comparable enforcement powers.
Privacy is a board-level risk
Customer trust, market access, and partnership eligibility all depend on demonstrable privacy compliance.
Subject rights are the new operational floor
Honouring access and erasure requests at scale requires data inventories that most organisations only build under regulatory pressure.
Direct answers
Does my US-based company need to comply with GDPR?+
Yes, if you process personal data of individuals located in the EU — GDPR applies extraterritorially regardless of where the controller or processor is established.
How is CPRA different from CCPA?+
CPRA (effective 2023) extends CCPA with new rights (correction, opt-out of sharing for cross-context behavioural advertising), creates a sensitive-personal-information category, and establishes the California Privacy Protection Agency as the dedicated enforcement body.
Is ISO 27701 a substitute for GDPR compliance?+
No. ISO 27701 certification demonstrates a robust Privacy Information Management System, which materially supports GDPR compliance, but does not replace the legal obligations of the regulation itself.
What is the status of EU–US data transfers after Privacy Shield?+
Privacy Shield was invalidated in 2020 (Schrems II). Transfers now rely on Standard Contractual Clauses, Binding Corporate Rules, or — since 2023 — the EU–US Data Privacy Framework adequacy decision, which itself faces ongoing legal challenge.
